ON July 29, 2026, Broadcom disclosed two critical vulnerabilities in VMware vCenter Server, CVE-2026-59309 and CVE-2026-59310, both with a CVSSv3.1 score of 9.8. CVE-2026-59309 represents an authentication bypass that allows unauthorized access to the vCenter management plane, while CVE-2026-59310 involves a directory traversal vulnerability that enables remote code execution. Exploitation does not require prior authentication, but attackers must have network access.
There is currently no known proof-of-concept for exploitation, making immediate patching essential as exploitation in the wild could occur. Organizations are urged to apply the updates suggested in Broadcom's security advisory promptly. Rapid7 customers can assess their exposure using specific vulnerability checks.